SlideShare a Scribd company logo
Extending Role-Based Policies to Wired Access
Madani Adjali & Scott Calzia
March, 2014
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
2 #AirheadsConf
Agenda
Platform Overview
Native AAA
ClearPass Policy Manager Integration
3
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Introducing the Aruba
Mobility Access Switch Family
• Security to wired access
– Flexible role-based access
– Policy moves from wireless to wired
• Operational simplicity
– Low-touch installation and configuration
– Dynamic configuration of user policies
– Integration with Aruba APs
• Simplify the network
– Reduce VLANs in the closet
– Extend logical configurations
• 802.11ac Ready
– Scaled to support high-density
deployments
– PoE+ on every switch port
– 10GbE uplinks (S2500/S3500)
4
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Mobility Access Switch
Capabilities
A. Ethernet Switch
• Layer 2/3 forwarding
• Native Role-based policy
enforcement
B. Integration with ClearPass
• Downloadable Role/ACL
• Captive Portal
C. Wired Access Point
• Tunneled Node
• Role-based policy
enforcement at Mobility
Controller
• Single policy for WLAN
and LAN
A. L2/L3
Forwarding
C. Wired AP
Mobility Access
Switch
Access Point
LAN Core
Mobility
Controller
AirWave
Management
Platform
ClearPass Policy
Manager
B. User-Role
Download
5
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S3500 Mobility Access Switch
• Designed for Wired Access
– 24/48 Port Models
– Wire-rate and non-blocking performance
– Role-based access with user visibility
– Per port PoE/PoE+
• ArubaStack
– Stack up to 8 devices
– Up to 384x GbE and 16x 10GbE
– Single management IP address
– Single configuration file
• Flexible Forwarding Options
– Traditional L2/L3 Switching
– Tunnel traffic to Mobility Controller
• Modular Components
– Field replaceable AC power supplies
• Optional redundant power supply
– Field replaceable fan tray
– Optional 4-port uplink module
• 1000BASE/10GBASE-x SFP/SFP+
PoE budget values are provided for single PSU and dual PSU configurations
SKU Ports PoE Budget
S3500-24F 24x1000BASE-x Not Applicable
S3500-24T 24x10/100/1000BASE-T Not Applicable
S3500-24P 24x10/100/1000BASE-T 400W | 689W
S3500-48T 48x10/100/1000BASE-T Not Applicable
S3500-48P 48x10/100/1000BASE-T 400W | 689W
S3500-48PF 48x10/100/1000BASE-T 850W | 1465W
6
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S3500: Front and Rear Views
• Modular Components
– Power Supplies
– Fan Tray
– Uplink Module
• Management
– Console (RJ45 Serial)
– Out-of-band Ethernet
– USB Storage
– LCD Display
• Dimensions & Airflow
– 1RU
– 1.75˝ (H) x 17.5˝ (W) x 17.5˝ (D)
– Front/Side to Rear Airflow
• Mounting Options
– 2 Post Rack (front & mid-mount)
– 4 Post Rack
– Wall Mount
• Limited Lifetime Warranty
Optional
Uplink Module
S3500 Rear View
USB
Console
Field-Replaceable
Fan Tray
Hot-Swappable Power Supplies
Ethernet
Out-of-Band
S3500-24F Front View
24x1000BASE-X SFP Ports
LCD
S3500-48P Front View
Fixed 10/100/1000BASE-T Ports
LCD
7
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S2500 Mobility Access Switch
• Designed for Wired Access
– 24/48 Port 10/100/1000BASE-T
– Wire-rate and non-blocking performance
– Role-based access with user visibility
– Per port PoE/PoE+
• ArubaStack
– Stack up to 8 devices
– Up to 384x GbE and 16x 10GbE
– Single management IP address
– Single configuration file
– Stackable with S3500
• Flexible Forwarding Options
– Traditional L2/L3 Switching
– Tunnel traffic to Mobility Controller
• Integrated Components
– Built in fans for quiet operation
– Fixed 4-port uplinks
• 1000BASE/10GBASE-x SFP/SFP+
SKU Ports PoE Budget
S2500-24T 24x 10/100/1000BASE-T Not Applicable
S2500-24P 24x 10/100/1000BASE-T 400W
S2500-48T 48x 10/100/1000BASE-T Not Applicable
S2500-48P 48x 10/100/1000BASE-T 400W
8
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S2500: Front and Rear Views
S2500 Front View
LCD
Display
Fixed 10/100/1000BASE-T Ports
• Fixed Components
– Built-in 4xSFP/SFP+ Uplinks
– Integrated Power Supply
• PoE Budget
– 400W
– PoE Priority Available
• Management
– Console (RJ45 & mUSB Serial)
– Out-of-band Ethernet
– USB Storage
– LCD Display
• Dimensions & Airflow
– 1RU
– 1.75˝ (H) x 17.5˝ (W) x 12˝ (D)
– Side to side airflow
• Mounting Options
– 2 Post Rack (Front)
– Wall & 2-Post Mid Mount
• Limited Lifetime Warranty
Fixed
4x 1000BASE-x/10GBASE-x
(SFP/SFP+) Ports
S2500 Rear View
USB Integrated
Power Supply
Ethernet
Out-of-Band
RJ-45 & Mini-USB
Console
Fixed Fans
9
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S2500: Front and Rear Views
• Designed for Wired Access
– 12/24/48 Port 10/100/1000BASE-T
– Wire-rate and non-blocking performance
– Role-based access with user visibility
– Per port PoE/PoE+
• ArubaStack
– Stack up to 8 devices
– Single management IP address
– Single configuration file
• Flexible Forwarding Options
– Traditional L2/L3 Switching
– Tunnel traffic to Mobility Controller
• Integrated Components
– Built in fans for quiet operation (24P/48P)
– Fanless (12P)
– Fixed 2-port (12P) & 4-port (24P/48P)
uplinks
• 1000BASE-x SFP
SKU Ports PoE Budget
S1500-12P 12x 10/100/1000BASE-T 120W
S1500-24P 24x 10/100/1000BASE-T 400W
S1500-48P 48x 10/100/1000BASE-T 400W
10
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S1500-24P/48P: Front &
Rear Views
S1500-24/48P Rear View
Console
USB
Fixed
4x 1000BASE-X
(SFP) Ports
48x 10/100/1000 (RJ45) Ports
• Fixed Components
– Built-in 4xSFP Uplinks
– Integrated Power Supply
• PoE Budget
– 400W
– PoE Priority Available
• Features & Scaling
– Same features as S2500/S3500
– Reduced scaling vs. S2500/S3500
• Management
– Console (RJ45)
– USB Storage
• Dimensions & Airflow
– 1RU
– 1.75˝ (H) x 17.5˝ (W) x 12˝ (D)
– Side to side airflow
• Mounting Options
– 2 Post Rack (Front)
– Wall & 2-Post Mid Mount
• Limited Lifetime Warranty
Integrated
Power Supply
Fixed Fans
Mode LEDs and
Selector
S1500-48P Front View
11
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
S1500-12P: Front & Rear Views
S1500-12P - Front View
USB
Console
RJ-45
12x 10/100/1000Base-T
With 8x PoE/PoE+)
2x 1000BASE-x
(SFP)
Mode LEDs and
Selector
Cooling Vents on
Top and Bottom for
Fanless Design
• Fixed Components
– Built-in 2xSFP Uplinks
– Integrated Power Supply
• PoE Budget
– 8x PoE/PoE+ with 120W Budget
– PoE Priority Available
• Features & Scaling
– Same features as S2500/S3500
– Reduced scaling vs. S2500/S3500
• Management
– Console (RJ45)
– USB Storage
• Dimensions & Airflow
- 1.72" (H) x 13" (W) x 8.9" (D)
– Fanless
• Mounting Options
– Desktop (Rubber feet included)
– Rack & Wall Mount (Included)
– Magnet Mount (Optional)
• Limited Lifetime Warranty
S1500-12P - Rear View
Integrated
Power Supply
Security Lock Slot
12
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Platform Comparison
Capability / Feature S3500-XXP S3500-XXT S2500-XXP S2500-XXT
S1500-
XXP
S1500-
12P
Number of Ports 24/48 24/48 24/48 24/48 24/48 12
10/100/1000 Fixed Ports Yes Yes Yes Yes Yes Yes
Line Rate Yes Yes Yes Yes Yes Yes
Uplink Performance 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 1G SFP 2 x 1G SFP
Uplinks Options Modular Modular Integrated Integrated Integrated Integrated
LCD Yes Yes Yes Yes No No
Modular Power Yes Yes No No No No
Dual Power Yes Yes No No No No
PoE/PoE+ (15.4W/30W) Yes N/A Yes N/A Yes Yes
PoE Budget (W) 400/689/1465 N/A 400 N/A 400 120
Max Simultaneous PoE/PoE+ 48A/48A N/A 25/13 N/A 25/13 7/4
Modular Fan (FRU) Yes Yes No No No No
ArubaStack Yes Yes Yes Yes Yes Yes
Max ArubaStack Members 8 8 8 8 8 8
Mixed Product Line ArubaStacks Yes Yes Yes Yes No No
Depth 17.5”/19.5”A 17.5” <12” <12” <12” <9”
Ambient Sound 48dB 48dB 42dB 42dB 42dB 0dB
List Price (24/48) $3,995B/$6,995B $3,195B/$5,495B $3,795/$6,795 $2,995/$5,195 $2,495/$4,595 $1,595
Note A: Assumes dual 1050W power supplies | Note B: Single power supply(600W for P SKU and 350W for T SKU) and no uplink module (S3500-4x10G - List $1495)
13
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Features & Capabilities
Overview
• Spanning Tree
- Multiple Spanning Tree (MSTP)
- Rapid PVST+
• Link Aggregation Group
• Hot Standby Link
• L2 Generic Router Encapsulation
• Voice VLAN
- LLDP-MED
- CDP Fingerprinting
• Port Security
- DHCP Snooping, DAI & IPSG
• Quality of Service
- Strict Priority Queuing
- 1 Rate Tri-Color Policing
• Ethernet OAM 802.3ah
Platform / Layer 2 Features Routing / Branch Features
• Routed Virtual Interfaces (RVI)
• Static Routing
• OSPFv2
- MD5 Authentication
- Route Filtering
• Policy Based Routing
• Virtual Router Redundancy Protocol
• L3 Generic Router Encapsulation
• Multicast
- PIM-SM
- IGMP Snooping/MLDv1
• Network Address Translation
• Stateful Firewall
• Site to Site VPN
- Includes OSPF over VPN
14
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Features & Capabilities
Overview (Cont.)
• Role Based User Access
• User Derived Roles
- MAC Address Variable Match
- DHCP Signature Match
- LLDP/CDP Phone Match
• AAA Authentication
- 802.1x
- MAC Auth
- Captive Portal (Internal/External)
• External Authentication Servers
- Radius
- TACACS+
- LDAP
• Radius Fail-Open
Authentication & Security Aruba Portfolio Integration
• Aruba Activate
• Mobility Controller
- Tunneled Node
- AirGroup
- Auto AP PoE Prioritization
- Auto AP QoS Trust
• Instant AP
- Auto AP PoE Prioritization
- Auto AP QoS Trust
- Rogue AP Enforcement
- VLAN Sharing
• ClearPass Policy Manager (CPPM)
- Downloadable Roles & ACLs
- Redirect to ClearPass Guest
15
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Native AAA
16
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Aruba AAA View Of The World
Manufacturers
Via MAC OUI
Operating Systems
Via DHCP
Fingerprinting
Our Mobility Access Switches see…
And our security enforcement model uses…
MAC
Addresses
Usernames/P
asswords
IP Phones
Via Device-Type
Fingerprinting
User-roles
…provisioned locally or dynamically
which simplifies AAA deployments
17
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
What is User-Role?
A user-role is a container that consists of:
• VLAN ID
• Access Control Lists
• QoS Profile
• Policer Profile
• Captive Portal Settings
• VoIP Profile
…A user-role can be referenced locally or passed
down via a Radius Vendor Specific Attribute
18
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
How Do I Implement User-
Roles?
•User Derivation Rules
• Manufacturers by Vendor OUI
– Instead of pre-populating a user database or a static MAC bypass list
with MAC addresses from the same vendor, create a UDR to match on
the Vendor’s OUI (first 6 digits or 24 bits) and assign a VLAN or user-
role.
• Operating Systems by DHCP Fingerprinting
– Operating systems and some classes of devices utilize unique DHCP
messages (e.g. the options they request, the order of the options). A
UDR can be created to match on that unique fingerprint or signature
and assign a VLAN or user-role.
• IP Phone by Device-Type Fingerprinting
– IP Phones and AAA don’t always get along. Device-Type fingerprinting
allows you to match on an IP Phone’s LLDP/CDP “phone” capability
announcement so you can create a UDR to assign a VLAN or user-role.
No External Radius Required!
19
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
How Do I Implement User-
Roles?
•Traditional AAA Services
• 802.1x
– For clients with 802.1x compatible supplicants, 802.1x provides secure
access using usernames/passwords and/or certificates. Authenticated
users can be assigned a default user-role or a specific user-role.
• MAC Authentication
– For network assets that do not support 802.1x, MAC authentication can
be used to allow access to the network. Authenticated users can be
assigned a default user-role or a specific user-role.
• Captive Portal
– For guest clients, a web page can be provided so that they can login
and gain access. Guest users can then be assigned a specific user-role
limiting their network access.
Supported with Internal and External Auth Servers!
20
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
Native AAA Demo
21
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
ClearPass Policy Manager Integration
22
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
#AirheadsConf
802.11n AP ClearPass
ClearPass Policy Manager
Integration
Mobility
Controller
1. User provides their
credentials and other
context to Authenticate
Context
• User: Joe Smith
• Role: Guest
• Device: Apple iPad
• Date: M-F, 8am-5pm
• Access: Internet
Mobility Access
Switch
2. ClearPass Policy
Manager returns Role
& Policy for
User/Device
3. Role & Policy pushed
to the Mobility Controller
for Role & Policy
Enforcement**
3. Role & Policy pushed
to the Mobility Access
Switch for Role & Policy
Enforcement
Policy Enforcement Policy Definition
**Roadmap
23
24
CONFIDENTIAL
© Copyright 2014. Aruba Networks, Inc.
All rights reserved
Thank You
#AirheadsConf

More Related Content

PPTX
Breakout - Airheads Macau 2013 - Unified Access: Deploying Mobility Access S...
PPTX
Shanghai Breakout: Aruba Mobility Access Switch Workshop
PDF
Electroducto - La mejor forma de entregar energía eléctrica
PPTX
Advanced Aruba Mobility Access Switch Workshop
PDF
Ds 8609 smart_router_74_c0022
PDF
Cisco UCS Solution EMC World 2015
PDF
8600 smart router-portfolio_overview
PPTX
RF characteristics and radio fundamentals
Breakout - Airheads Macau 2013 - Unified Access: Deploying Mobility Access S...
Shanghai Breakout: Aruba Mobility Access Switch Workshop
Electroducto - La mejor forma de entregar energía eléctrica
Advanced Aruba Mobility Access Switch Workshop
Ds 8609 smart_router_74_c0022
Cisco UCS Solution EMC World 2015
8600 smart router-portfolio_overview
RF characteristics and radio fundamentals

What's hot (20)

PDF
Cisco Live! :: Deploying SIP Trunks with Cisco Unified Border Element (CUBE/v...
PPTX
WLAN Architecture - Considerations
PDF
Aerohive AP370 802.11ac Wireless Access Point
PDF
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
PDF
Ds 8630 smart_router_74_c0025
PDF
Huawei s5700 li switch datasheet
PDF
Guía de referencia Switches Avaya
PDF
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
PPTX
Scalable and Secure Connectivity for Seamless Cloud Evolution
PDF
PDF
IBM System Networking Portfolio Update, June 2014
PDF
8600_compar
PPTX
HP BladeSystem Interconnects
PDF
Audinate avb white paper v1.2
PDF
catalyst-switching-poster
PDF
Ds 8625 smart_router_74_c0130 (1)
PDF
Cisco 4500 switch modules datasheet
PDF
Ds 8615 smart_router_74_c0001
PPTX
BGP and Traffic Engineering with Akamai
PDF
Mits 5G brief solution 2021
Cisco Live! :: Deploying SIP Trunks with Cisco Unified Border Element (CUBE/v...
WLAN Architecture - Considerations
Aerohive AP370 802.11ac Wireless Access Point
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Ds 8630 smart_router_74_c0025
Huawei s5700 li switch datasheet
Guía de referencia Switches Avaya
Cisco Live! :: Cisco ASR 9000 Architecture :: BRKARC-2003 | Las Vegas 2017
Scalable and Secure Connectivity for Seamless Cloud Evolution
IBM System Networking Portfolio Update, June 2014
8600_compar
HP BladeSystem Interconnects
Audinate avb white paper v1.2
catalyst-switching-poster
Ds 8625 smart_router_74_c0130 (1)
Cisco 4500 switch modules datasheet
Ds 8615 smart_router_74_c0001
BGP and Traffic Engineering with Akamai
Mits 5G brief solution 2021
Ad

Similar to Extending Role Based Policies to Wired Access (20)

PDF
Mobility access switches_madani adjali
PDF
Mobility switch security architecture scott calzia madani adjali
PDF
Migrating to the 7200 controller george anderson marcus christensen
PPTX
Unified access with Aruba Mobility Access Switches – Live Demo
PDF
2012 ah vegas unified access fundamentals
PDF
Aruba 3810M 24SFP+ 250W Switch-PSN1009647820SEEN_2.pdf
PPTX
Aruba 2930 f switch campus switching
PDF
Aruba 2930F Switch Series Datasheet
PDF
Aruba s3500 installation guide
PDF
Aruba 7000 Series Mobility Controller Data Sheet
PDF
Building an aruba proof of concept lab javier urtubia
PDF
Instant overview gokul_rajagopalan
PDF
HP_Networking_Aruba_Solution Gestion y configuraciones
PDF
Aruba 2920 Switch Series Data Sheet
PDF
Ap90 series
PDF
Aruba 2530 Switch Series Data Sheet
PPTX
Aruba CX 6300 Switch Series Customer Presentation-a00091191enw.pptx
PPTX
Airheads Meetups: 8400 Presentation
PPTX
aruba network
PPTX
Aruba Netwrok(1).pptx
Mobility access switches_madani adjali
Mobility switch security architecture scott calzia madani adjali
Migrating to the 7200 controller george anderson marcus christensen
Unified access with Aruba Mobility Access Switches – Live Demo
2012 ah vegas unified access fundamentals
Aruba 3810M 24SFP+ 250W Switch-PSN1009647820SEEN_2.pdf
Aruba 2930 f switch campus switching
Aruba 2930F Switch Series Datasheet
Aruba s3500 installation guide
Aruba 7000 Series Mobility Controller Data Sheet
Building an aruba proof of concept lab javier urtubia
Instant overview gokul_rajagopalan
HP_Networking_Aruba_Solution Gestion y configuraciones
Aruba 2920 Switch Series Data Sheet
Ap90 series
Aruba 2530 Switch Series Data Sheet
Aruba CX 6300 Switch Series Customer Presentation-a00091191enw.pptx
Airheads Meetups: 8400 Presentation
aruba network
Aruba Netwrok(1).pptx
Ad

More from Aruba, a Hewlett Packard Enterprise company (20)

PPTX
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
PPTX
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
PPTX
Airheads Tech Talks: Advanced Clustering in AOS 8.x
PPTX
EMEA Airheads_ Advance Aruba Central
PPTX
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
PPTX
EMEA Airheads- Switch stacking_ ArubaOS Switch
PPTX
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
PPTX
PPTX
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
PPTX
EMEA Airheads- Aruba Central with Instant AP
PPTX
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
PPTX
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
PPTX
EMEA Airheads - AP Discovery Logic and AP Deployment
PPTX
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
PPTX
EMEA Airheads- Manage Devices at Branch Office (BOC)
PPTX
EMEA Airheads - What does AirMatch do differently?v2
PPTX
Airheads Meetups: Ekahau Presentation
PPTX
Airheads Meetups- High density WLAN
PPTX
Airheads Meetups- Avans Hogeschool goes Aruba
PPTX
EMEA Airheads - Configuring different APIs in Aruba 8.x
Airheads Tech Talks: Cloud Guest SSID on Aruba Central
Airheads Tech Talks: Understanding ClearPass OnGuard Agents
Airheads Tech Talks: Advanced Clustering in AOS 8.x
EMEA Airheads_ Advance Aruba Central
EMEA Airheads_ Aruba AppRF – AOS 6.x & 8.x
EMEA Airheads- Switch stacking_ ArubaOS Switch
EMEA Airheads- LACP and distributed LACP – ArubaOS Switch
EMEA Airheads- Virtual Switching Framework- Aruba OS Switch
EMEA Airheads- Aruba Central with Instant AP
EMEA Airheads- AirGroup profiling changes across 8.1 & 8.2 – ArubaOS 8.x
EMEA Airheads- Getting Started with the ClearPass REST API – CPPM
EMEA Airheads - AP Discovery Logic and AP Deployment
EMEA Airheads- Layer-3 Redundancy for Mobility Master - ArubaOS 8.x
EMEA Airheads- Manage Devices at Branch Office (BOC)
EMEA Airheads - What does AirMatch do differently?v2
Airheads Meetups: Ekahau Presentation
Airheads Meetups- High density WLAN
Airheads Meetups- Avans Hogeschool goes Aruba
EMEA Airheads - Configuring different APIs in Aruba 8.x

Extending Role Based Policies to Wired Access

  • 1. Extending Role-Based Policies to Wired Access Madani Adjali & Scott Calzia March, 2014
  • 2. CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved 2 #AirheadsConf Agenda Platform Overview Native AAA ClearPass Policy Manager Integration
  • 3. 3 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Introducing the Aruba Mobility Access Switch Family • Security to wired access – Flexible role-based access – Policy moves from wireless to wired • Operational simplicity – Low-touch installation and configuration – Dynamic configuration of user policies – Integration with Aruba APs • Simplify the network – Reduce VLANs in the closet – Extend logical configurations • 802.11ac Ready – Scaled to support high-density deployments – PoE+ on every switch port – 10GbE uplinks (S2500/S3500)
  • 4. 4 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Mobility Access Switch Capabilities A. Ethernet Switch • Layer 2/3 forwarding • Native Role-based policy enforcement B. Integration with ClearPass • Downloadable Role/ACL • Captive Portal C. Wired Access Point • Tunneled Node • Role-based policy enforcement at Mobility Controller • Single policy for WLAN and LAN A. L2/L3 Forwarding C. Wired AP Mobility Access Switch Access Point LAN Core Mobility Controller AirWave Management Platform ClearPass Policy Manager B. User-Role Download
  • 5. 5 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S3500 Mobility Access Switch • Designed for Wired Access – 24/48 Port Models – Wire-rate and non-blocking performance – Role-based access with user visibility – Per port PoE/PoE+ • ArubaStack – Stack up to 8 devices – Up to 384x GbE and 16x 10GbE – Single management IP address – Single configuration file • Flexible Forwarding Options – Traditional L2/L3 Switching – Tunnel traffic to Mobility Controller • Modular Components – Field replaceable AC power supplies • Optional redundant power supply – Field replaceable fan tray – Optional 4-port uplink module • 1000BASE/10GBASE-x SFP/SFP+ PoE budget values are provided for single PSU and dual PSU configurations SKU Ports PoE Budget S3500-24F 24x1000BASE-x Not Applicable S3500-24T 24x10/100/1000BASE-T Not Applicable S3500-24P 24x10/100/1000BASE-T 400W | 689W S3500-48T 48x10/100/1000BASE-T Not Applicable S3500-48P 48x10/100/1000BASE-T 400W | 689W S3500-48PF 48x10/100/1000BASE-T 850W | 1465W
  • 6. 6 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S3500: Front and Rear Views • Modular Components – Power Supplies – Fan Tray – Uplink Module • Management – Console (RJ45 Serial) – Out-of-band Ethernet – USB Storage – LCD Display • Dimensions & Airflow – 1RU – 1.75˝ (H) x 17.5˝ (W) x 17.5˝ (D) – Front/Side to Rear Airflow • Mounting Options – 2 Post Rack (front & mid-mount) – 4 Post Rack – Wall Mount • Limited Lifetime Warranty Optional Uplink Module S3500 Rear View USB Console Field-Replaceable Fan Tray Hot-Swappable Power Supplies Ethernet Out-of-Band S3500-24F Front View 24x1000BASE-X SFP Ports LCD S3500-48P Front View Fixed 10/100/1000BASE-T Ports LCD
  • 7. 7 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S2500 Mobility Access Switch • Designed for Wired Access – 24/48 Port 10/100/1000BASE-T – Wire-rate and non-blocking performance – Role-based access with user visibility – Per port PoE/PoE+ • ArubaStack – Stack up to 8 devices – Up to 384x GbE and 16x 10GbE – Single management IP address – Single configuration file – Stackable with S3500 • Flexible Forwarding Options – Traditional L2/L3 Switching – Tunnel traffic to Mobility Controller • Integrated Components – Built in fans for quiet operation – Fixed 4-port uplinks • 1000BASE/10GBASE-x SFP/SFP+ SKU Ports PoE Budget S2500-24T 24x 10/100/1000BASE-T Not Applicable S2500-24P 24x 10/100/1000BASE-T 400W S2500-48T 48x 10/100/1000BASE-T Not Applicable S2500-48P 48x 10/100/1000BASE-T 400W
  • 8. 8 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S2500: Front and Rear Views S2500 Front View LCD Display Fixed 10/100/1000BASE-T Ports • Fixed Components – Built-in 4xSFP/SFP+ Uplinks – Integrated Power Supply • PoE Budget – 400W – PoE Priority Available • Management – Console (RJ45 & mUSB Serial) – Out-of-band Ethernet – USB Storage – LCD Display • Dimensions & Airflow – 1RU – 1.75˝ (H) x 17.5˝ (W) x 12˝ (D) – Side to side airflow • Mounting Options – 2 Post Rack (Front) – Wall & 2-Post Mid Mount • Limited Lifetime Warranty Fixed 4x 1000BASE-x/10GBASE-x (SFP/SFP+) Ports S2500 Rear View USB Integrated Power Supply Ethernet Out-of-Band RJ-45 & Mini-USB Console Fixed Fans
  • 9. 9 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S2500: Front and Rear Views • Designed for Wired Access – 12/24/48 Port 10/100/1000BASE-T – Wire-rate and non-blocking performance – Role-based access with user visibility – Per port PoE/PoE+ • ArubaStack – Stack up to 8 devices – Single management IP address – Single configuration file • Flexible Forwarding Options – Traditional L2/L3 Switching – Tunnel traffic to Mobility Controller • Integrated Components – Built in fans for quiet operation (24P/48P) – Fanless (12P) – Fixed 2-port (12P) & 4-port (24P/48P) uplinks • 1000BASE-x SFP SKU Ports PoE Budget S1500-12P 12x 10/100/1000BASE-T 120W S1500-24P 24x 10/100/1000BASE-T 400W S1500-48P 48x 10/100/1000BASE-T 400W
  • 10. 10 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S1500-24P/48P: Front & Rear Views S1500-24/48P Rear View Console USB Fixed 4x 1000BASE-X (SFP) Ports 48x 10/100/1000 (RJ45) Ports • Fixed Components – Built-in 4xSFP Uplinks – Integrated Power Supply • PoE Budget – 400W – PoE Priority Available • Features & Scaling – Same features as S2500/S3500 – Reduced scaling vs. S2500/S3500 • Management – Console (RJ45) – USB Storage • Dimensions & Airflow – 1RU – 1.75˝ (H) x 17.5˝ (W) x 12˝ (D) – Side to side airflow • Mounting Options – 2 Post Rack (Front) – Wall & 2-Post Mid Mount • Limited Lifetime Warranty Integrated Power Supply Fixed Fans Mode LEDs and Selector S1500-48P Front View
  • 11. 11 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf S1500-12P: Front & Rear Views S1500-12P - Front View USB Console RJ-45 12x 10/100/1000Base-T With 8x PoE/PoE+) 2x 1000BASE-x (SFP) Mode LEDs and Selector Cooling Vents on Top and Bottom for Fanless Design • Fixed Components – Built-in 2xSFP Uplinks – Integrated Power Supply • PoE Budget – 8x PoE/PoE+ with 120W Budget – PoE Priority Available • Features & Scaling – Same features as S2500/S3500 – Reduced scaling vs. S2500/S3500 • Management – Console (RJ45) – USB Storage • Dimensions & Airflow - 1.72" (H) x 13" (W) x 8.9" (D) – Fanless • Mounting Options – Desktop (Rubber feet included) – Rack & Wall Mount (Included) – Magnet Mount (Optional) • Limited Lifetime Warranty S1500-12P - Rear View Integrated Power Supply Security Lock Slot
  • 12. 12 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Platform Comparison Capability / Feature S3500-XXP S3500-XXT S2500-XXP S2500-XXT S1500- XXP S1500- 12P Number of Ports 24/48 24/48 24/48 24/48 24/48 12 10/100/1000 Fixed Ports Yes Yes Yes Yes Yes Yes Line Rate Yes Yes Yes Yes Yes Yes Uplink Performance 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 10G SFP+ 4 x 1G SFP 2 x 1G SFP Uplinks Options Modular Modular Integrated Integrated Integrated Integrated LCD Yes Yes Yes Yes No No Modular Power Yes Yes No No No No Dual Power Yes Yes No No No No PoE/PoE+ (15.4W/30W) Yes N/A Yes N/A Yes Yes PoE Budget (W) 400/689/1465 N/A 400 N/A 400 120 Max Simultaneous PoE/PoE+ 48A/48A N/A 25/13 N/A 25/13 7/4 Modular Fan (FRU) Yes Yes No No No No ArubaStack Yes Yes Yes Yes Yes Yes Max ArubaStack Members 8 8 8 8 8 8 Mixed Product Line ArubaStacks Yes Yes Yes Yes No No Depth 17.5”/19.5”A 17.5” <12” <12” <12” <9” Ambient Sound 48dB 48dB 42dB 42dB 42dB 0dB List Price (24/48) $3,995B/$6,995B $3,195B/$5,495B $3,795/$6,795 $2,995/$5,195 $2,495/$4,595 $1,595 Note A: Assumes dual 1050W power supplies | Note B: Single power supply(600W for P SKU and 350W for T SKU) and no uplink module (S3500-4x10G - List $1495)
  • 13. 13 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Features & Capabilities Overview • Spanning Tree - Multiple Spanning Tree (MSTP) - Rapid PVST+ • Link Aggregation Group • Hot Standby Link • L2 Generic Router Encapsulation • Voice VLAN - LLDP-MED - CDP Fingerprinting • Port Security - DHCP Snooping, DAI & IPSG • Quality of Service - Strict Priority Queuing - 1 Rate Tri-Color Policing • Ethernet OAM 802.3ah Platform / Layer 2 Features Routing / Branch Features • Routed Virtual Interfaces (RVI) • Static Routing • OSPFv2 - MD5 Authentication - Route Filtering • Policy Based Routing • Virtual Router Redundancy Protocol • L3 Generic Router Encapsulation • Multicast - PIM-SM - IGMP Snooping/MLDv1 • Network Address Translation • Stateful Firewall • Site to Site VPN - Includes OSPF over VPN
  • 14. 14 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Features & Capabilities Overview (Cont.) • Role Based User Access • User Derived Roles - MAC Address Variable Match - DHCP Signature Match - LLDP/CDP Phone Match • AAA Authentication - 802.1x - MAC Auth - Captive Portal (Internal/External) • External Authentication Servers - Radius - TACACS+ - LDAP • Radius Fail-Open Authentication & Security Aruba Portfolio Integration • Aruba Activate • Mobility Controller - Tunneled Node - AirGroup - Auto AP PoE Prioritization - Auto AP QoS Trust • Instant AP - Auto AP PoE Prioritization - Auto AP QoS Trust - Rogue AP Enforcement - VLAN Sharing • ClearPass Policy Manager (CPPM) - Downloadable Roles & ACLs - Redirect to ClearPass Guest
  • 15. 15 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Native AAA
  • 16. 16 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Aruba AAA View Of The World Manufacturers Via MAC OUI Operating Systems Via DHCP Fingerprinting Our Mobility Access Switches see… And our security enforcement model uses… MAC Addresses Usernames/P asswords IP Phones Via Device-Type Fingerprinting User-roles …provisioned locally or dynamically which simplifies AAA deployments
  • 17. 17 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf What is User-Role? A user-role is a container that consists of: • VLAN ID • Access Control Lists • QoS Profile • Policer Profile • Captive Portal Settings • VoIP Profile …A user-role can be referenced locally or passed down via a Radius Vendor Specific Attribute
  • 18. 18 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf How Do I Implement User- Roles? •User Derivation Rules • Manufacturers by Vendor OUI – Instead of pre-populating a user database or a static MAC bypass list with MAC addresses from the same vendor, create a UDR to match on the Vendor’s OUI (first 6 digits or 24 bits) and assign a VLAN or user- role. • Operating Systems by DHCP Fingerprinting – Operating systems and some classes of devices utilize unique DHCP messages (e.g. the options they request, the order of the options). A UDR can be created to match on that unique fingerprint or signature and assign a VLAN or user-role. • IP Phone by Device-Type Fingerprinting – IP Phones and AAA don’t always get along. Device-Type fingerprinting allows you to match on an IP Phone’s LLDP/CDP “phone” capability announcement so you can create a UDR to assign a VLAN or user-role. No External Radius Required!
  • 19. 19 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf How Do I Implement User- Roles? •Traditional AAA Services • 802.1x – For clients with 802.1x compatible supplicants, 802.1x provides secure access using usernames/passwords and/or certificates. Authenticated users can be assigned a default user-role or a specific user-role. • MAC Authentication – For network assets that do not support 802.1x, MAC authentication can be used to allow access to the network. Authenticated users can be assigned a default user-role or a specific user-role. • Captive Portal – For guest clients, a web page can be provided so that they can login and gain access. Guest users can then be assigned a specific user-role limiting their network access. Supported with Internal and External Auth Servers!
  • 20. 20 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf Native AAA Demo
  • 21. 21 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf ClearPass Policy Manager Integration
  • 22. 22 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved #AirheadsConf 802.11n AP ClearPass ClearPass Policy Manager Integration Mobility Controller 1. User provides their credentials and other context to Authenticate Context • User: Joe Smith • Role: Guest • Device: Apple iPad • Date: M-F, 8am-5pm • Access: Internet Mobility Access Switch 2. ClearPass Policy Manager returns Role & Policy for User/Device 3. Role & Policy pushed to the Mobility Controller for Role & Policy Enforcement** 3. Role & Policy pushed to the Mobility Access Switch for Role & Policy Enforcement Policy Enforcement Policy Definition **Roadmap
  • 23. 23
  • 24. 24 CONFIDENTIAL © Copyright 2014. Aruba Networks, Inc. All rights reserved Thank You #AirheadsConf

Editor's Notes

  • #12: 30:24 – 32:44
  • #24: 21:44 – 24:16